CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-46038

    Last Modified: 21 Nov 2024

    A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context-dependent).

    Published: 5 Jan 2022
    0
    Low

    CVE-2022-1214

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Jan 2022
    8
    High

    CVE-2021-43816

    Last Modified: 22 Apr 2025

    containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.

    Published: 5 Jan 2022
    5.5
    Medium

    CVE-2021-45833

    Last Modified: 21 Nov 2024

    A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).

    Published: 5 Jan 2022
    5.5
    Medium

    CVE-2021-41043

    Last Modified: 21 Nov 2024

    Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

    Published: 5 Jan 2022
    —
    Unknown

    CVE-2022-22645

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Jan 2022
    —
    Unknown

    CVE-2022-22649

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Jan 2022
    7.8
    High

    CVE-2021-22045

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.

    Published: 4 Jan 2022
    7.8
    High

    CVE-2021-41388

    Last Modified: 21 Nov 2024

    Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user can connect and call external methods defined in XPC service as root, elevating their privilege to the highest level.

    Published: 4 Jan 2022
    7.6
    High

    CVE-2022-21649

    Last Modified: 22 Apr 2025

    Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

    Published: 4 Jan 2022
    7.6
    High

    CVE-2022-21650

    Last Modified: 22 Apr 2025

    Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS attack is triggered upon a user viewing the file. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.

    Published: 4 Jan 2022
    8.2
    High

    CVE-2022-21648

    Last Modified: 23 Apr 2025

    Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

    Published: 4 Jan 2022
    7.7
    High

    CVE-2022-21647

    Last Modified: 23 Apr 2025

    CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit, which can lead to SQL injection. Users are advised to upgrade to v4.1.6 or later. Users unable to upgrade as advised to not use the `old()` function and form_helper nor `RedirectResponse::withInput()` and `redirect()->withInput()`.

    Published: 4 Jan 2022
    9.1
    Critical

    CVE-2022-21644

    Last Modified: 23 Apr 2025

    USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.

    Published: 4 Jan 2022
    —
    Unknown

    CVE-2021-41610

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-27339. Reason: This candidate is a reservation duplicate of CVE-2020-27339. Notes: All CVE users should reference CVE-2020-27339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Jan 2022
    10
    Critical

    CVE-2022-21643

    Last Modified: 23 Apr 2025

    USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.

    Published: 4 Jan 2022
    8.8
    High

    CVE-2021-43852

    Last Modified: 23 Apr 2025

    OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution. This issue has been patched in version 4.2.8. Users unable to upgrade may configure a firewall to drop requests containing next strings: `__proto__` , `constructor[prototype]`, and `constructor.prototype` to mitigate this issue.

    Published: 4 Jan 2022
    6.8
    Medium

    CVE-2021-43850

    Last Modified: 22 Apr 2025

    Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/message-bus/_diagnostics` path. The impact of this vulnerability is greater on multisite Discourse instances (where multiple forums are served from a single application server) where any admin user on any of the forums are able to visit the `/message-bus/_diagnostics` path. The problem has been patched. Please upgrade to 2.8.0.beta10 or 2.7.12. No workarounds for this issue exist.

    Published: 4 Jan 2022
    10
    Critical

    CVE-2021-43832

    Last Modified: 23 Apr 2025

    Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users haven't setup Role-based access control (RBAC) with-in spinnaker, this enables remote execution and access to deploy almost any resources on any account. Patches are available on the latest releases of the supported branches and users are advised to upgrade as soon as possible. Users unable to upgrade should enable RBAC on ALL accounts and applications. This mitigates the ability of a pipeline to affect any accounts. Block application access unless permission are enabled. Users should make sure ALL application creation is restricted via appropriate wildcards.

    Published: 4 Jan 2022
    6.1
    Medium

    CVE-2021-43677

    Last Modified: 21 Nov 2024

    Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.

    Published: 4 Jan 2022
    6.9
    Medium

    CVE-2021-41236

    Last Modified: 23 Apr 2025

    OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must have permission to create or edit an email template. For successful payload, execution the attacked user must preview a vulnerable email template. There are no workarounds that address this vulnerability. Users are advised to upgrade as soon as is possible.

    Published: 4 Jan 2022
    9.8
    Critical

    CVE-2021-24042

    Last Modified: 22 May 2025

    The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious actor.

    Published: 4 Jan 2022
    6.6
    Medium

    CVE-2021-39143

    Last Modified: 22 Apr 2025

    Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the paths in that deployment don't override system files. This would allow an attacker to override files on the container, POTENTIALLY introducing a MITM type attack vector by replacing libraries or injecting wrapper files. Users are advised to update as soon as possible. For users unable to update disable Google AppEngine deployments and/or disable artifacts that provide TARs.

    Published: 4 Jan 2022
    9.8
    Critical

    CVE-2022-0086

    Last Modified: 21 Nov 2024

    uppy is vulnerable to Server-Side Request Forgery (SSRF)

    Published: 4 Jan 2022
    7.5
    High

    CVE-2021-3845

    Last Modified: 21 Nov 2024

    ws-scrcpy is vulnerable to External Control of File Name or Path

    Published: 4 Jan 2022
    6.5
    Medium

    CVE-2022-20023

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198608; Issue ID: ALPS06198608.

    Published: 4 Jan 2022
    6.5
    Medium

    CVE-2022-20022

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198578; Issue ID: ALPS06198578.

    Published: 4 Jan 2022
    6.5
    Medium

    CVE-2022-20021

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198513; Issue ID: ALPS06198513.

    Published: 4 Jan 2022
    5.5
    Medium

    CVE-2022-20020

    Last Modified: 21 Nov 2024

    In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05943906; Issue ID: ALPS05943906.

    Published: 4 Jan 2022
    5.5
    Medium

    CVE-2022-20019

    Last Modified: 22 May 2025

    In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917620; Issue ID: ALPS05917620.

    Published: 4 Jan 2022
    4.4
    Medium

    CVE-2022-20018

    Last Modified: 21 Nov 2024

    In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863018; Issue ID: ALPS05863018.

    Published: 4 Jan 2022
    6.7
    Medium

    CVE-2022-20016

    Last Modified: 21 Nov 2024

    In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862986; Issue ID: ALPS05862986.

    Published: 4 Jan 2022
    4.4
    Medium

    CVE-2022-20015

    Last Modified: 21 Nov 2024

    In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862966; Issue ID: ALPS05862966.

    Published: 4 Jan 2022
    6.7
    Medium

    CVE-2022-20014

    Last Modified: 22 May 2025

    In vow driver, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05857308; Issue ID: ALPS05857308.

    Published: 4 Jan 2022
    6.4
    Medium

    CVE-2022-20013

    Last Modified: 21 Nov 2024

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05837742.

    Published: 4 Jan 2022
    7.8
    High

    CVE-2022-20012

    Last Modified: 21 Nov 2024

    In mdp driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05836478; Issue ID: ALPS05836478.

    Published: 4 Jan 2022
    6.5
    Medium

    CVE-2021-41789

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of service from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20190426015; Issue ID: GN20190426015.

    Published: 4 Jan 2022
    7.5
    High

    CVE-2021-40148

    Last Modified: 21 Nov 2024

    In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID: ALPS05886933.

    Published: 4 Jan 2022
    9.8
    Critical

    CVE-2021-45389

    Last Modified: 21 Nov 2024

    A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

    Published: 4 Jan 2022
    7.8
    High

    CVE-2021-45912

    Last Modified: 21 Nov 2024

    An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.

    Published: 4 Jan 2022
    7.5
    High

    CVE-2021-3842

    Last Modified: 21 Nov 2024

    nltk is vulnerable to Inefficient Regular Expression Complexity

    Published: 4 Jan 2022
    7.8
    High

    CVE-2021-45980

    Last Modified: 21 Nov 2024

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

    Published: 4 Jan 2022
    7.8
    High

    CVE-2021-45979

    Last Modified: 21 Nov 2024

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

    Published: 4 Jan 2022
    7.8
    High

    CVE-2021-45978

    Last Modified: 21 Nov 2024

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

    Published: 4 Jan 2022
    7.2
    High

    CVE-2021-45913

    Last Modified: 21 Nov 2024

    A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.

    Published: 4 Jan 2022
    9.8
    Critical

    CVE-2021-43711

    Last Modified: 21 Nov 2024

    The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.

    Published: 4 Jan 2022
    3.3
    Low

    CVE-2021-44168

    Last Modified: 24 Oct 2025

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

    Published: 4 Jan 2022
    7.1
    High

    CVE-2021-31833

    Last Modified: 21 Nov 2024

    Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would usually be prevented by MACC. This would require the attacker to rename the specified binary to match name of any configured updater and perform a specific set of steps, resulting in the renamed binary to be to run.

    Published: 4 Jan 2022
    9.1
    Critical

    CVE-2021-40525

    Last Modified: 21 Nov 2024

    Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.

    Published: 4 Jan 2022
    6.5
    Medium

    CVE-2021-40111

    Last Modified: 21 Nov 2024

    In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial Of Service attack. The IMAP user needs to be authenticated to exploit this vulnerability. This affected Apache James prior to version 3.6.1. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade.

    Published: 4 Jan 2022